Compiled from 52 monitored sources · 240 articles reviewed
Today’s Briefing
Australian Federal Police arrested two alleged TeamPCP operators behind the Shai-Hulud worm and related supply chain attacks, working with the FBI. CISA added CVE-2023-49105 in ownCloud, CVE-2026-53362 in the Linux kernel IPv6 subsystem, CVE-2026-66384 in JFrog Artifactory, and CVE-2015-5287 in Red Hat ABRT to the KEV catalogue on evidence of active exploitation. The NCSC published guidance on disruptive cyber activity targeting internet-exposed systems and edge devices. Ubiquiti released an advisory covering multiple critical vulnerabilities in UniFi products enabling command injection, authentication bypass, and privilege escalation.
Top Stories
- Australian cops cuff alleged TeamPCP masterminds
- CC-4837 - Ubiquiti Releases Security Advisory Bulletin for Multiple Critical Vulnerabilities in UniFi Products
- Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
- CISA Adds Three Known Exploited Vulnerabilities to Catalog
- Mitsubishi Electric CNC Series (Update A)
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.